GDPR Compliance

How we protect your data rights under the General Data Protection Regulation

Our Commitment to Data Protection

At GooScale, we are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR). We believe in transparency about how we collect, use, and protect your personal data.

Our team of experts, including our dedicated Data Protection Officer, works diligently to ensure that your data is handled securely and in accordance with GDPR requirements. We regularly review and update our practices to maintain the highest standards of data protection.

Your Rights Under GDPR

Right to access your personal data

You have the right to request a copy of your personal data and to verify the lawfulness of processing.

Right to rectification of inaccurate data

You can request corrections to your personal data if it is inaccurate or incomplete.

Right to erasure ("right to be forgotten")

Also known as "right to be forgotten," you can request the deletion of your personal data.

Right to restrict processing

You can request to limit the way we use your personal data.

Right to data portability

You can request to receive your data in a structured format or have it transferred to another service.

Right to object to processing

You can object to the processing of your personal data for marketing and other purposes.

How We Protect Your Data

Data Encryption

We use industry-standard encryption protocols to protect your data during transmission and storage.

Access Controls

Strict access controls and authentication measures protect your data from unauthorized access.

Security Monitoring

Continuous monitoring and regular security audits ensure the safety of your data.

Regular Backups

Automated backup systems ensure your data is safely stored and can be recovered if needed.

Data Processing Activities

We process personal data only when we have a legal basis to do so. Our processing activities are documented and regularly reviewed to ensure compliance with GDPR principles.

Contract Performance

Processing necessary to provide our services and fulfill our contractual obligations to you.

Consent-based Processing

Processing activities that require your explicit consent, such as marketing communications.

Legitimate Interests

Processing necessary for our legitimate business interests, balanced against your rights and freedoms.

Legal Obligations

Processing required to comply with our legal obligations under applicable laws.

International Data Transfers

When we transfer your personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission for certain countries
  • Binding Corporate Rules for transfers within our corporate group

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

Account Data

Retained for the duration of your account plus 12 months after account closure

Transaction Data

Kept for 7 years to comply with tax and accounting requirements

Marketing Data

Retained until you withdraw consent or object to processing

Automated Decision Making

We may use automated decision-making in the following circumstances:

Fraud Prevention

Automated systems to detect and prevent fraudulent activities

Service Performance

Automated processes to ensure optimal service delivery and platform performance

You have the right to obtain human intervention, express your point of view, and contest any automated decisions that significantly affect you.

Technical and Organizational Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Encryption

  • Data encryption in transit (TLS)
  • Data encryption at rest
  • Secure key management

Access Control

  • Multi-factor authentication
  • Principle of least privilege
  • Access logging and auditing

Monitoring

  • Real-time security monitoring
  • Incident response procedures
  • Regular vulnerability assessments

Business Continuity

  • Regular data backups
  • Disaster recovery planning
  • Regular recovery testing

Contact Our DPO

For any questions about your data rights or to exercise your GDPR rights, please contact our Data Protection Officer:

Data Protection Officer

Email: contact@gooscale.com

Our Response Time

We aim to respond to all GDPR-related requests within 30 days. In complex cases, we may need up to 90 days, but we will keep you informed throughout the process. There is no fee for exercising your GDPR rights unless requests are manifestly unfounded or excessive.